Information disclosure in Zoom Video Communications, Inc. products - CVE-2022-28764

 

Information disclosure in Zoom Video Communications, Inc. products - CVE-2022-28764

Published: November 11, 2022


Vulnerability identifier: #VU69235
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28764
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to the application does not clear data from the local SQL database after a meeting ends and also uses an insufficiently secure per-device key to encrypt meetings data. A local user can obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.


Affected software

Zoom Workplace App for iOS
Zoom Workplace App for Android
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
Zoom Rooms Client for Windows
Zoom Rooms Client for macOS
Virtual Desktop Infrastructure (VDI)

How to mitigate CVE-2022-28764

Install updates from vendor's website.

Zoom Workplace App for iOS - update to 5.12.8 5518
Zoom Workplace Desktop App for Windows - update to 5.12.6 10137
Zoom Workplace Desktop App for macOS - update to 5.12.6 12435
Zoom Workplace App for Android - update to 5.12.8 9880
Zoom Workplace Desktop App for Linux - update to 5.12.6 173
Zoom Rooms Client for Windows - update to 5.12.6 2076
Zoom Rooms Client for macOS - update to 5.12.6 1918
Virtual Desktop Infrastructure (VDI) - update to 5.12.6

External References

Related Security Bulletins